MEDIUM5.3
GHSA-6h67-934r-82g7
Bypass of field access control in strapi-plugin-protected-populate
Quick fix
GHSA-6h67-934r-82g7 — strapi-plugin-protected-populate: upgrade to the fixed version with the command below.
npm install strapi-plugin-protected-populate@1.3.4Details
### Impact Users are able to bypass the field level security. This means fields that they where not allowed to populate could be populated anyway even in the event that they tried to populate something that they don't have access to.
### Patches This issue has been patched in 1.3.4
### Workarounds None
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/strapi-plugin-protected-populate
Introduced in:
0Fixed in: 1.3.4Fix
npm install strapi-plugin-protected-populate@1.3.4References
- https://github.com/strapi-community/strapi-plugin-protected-populate/security/advisories/GHSA-6h67-934r-82g7[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-48218[ADVISORY]
- https://github.com/strapi-community/strapi-plugin-protected-populate/commit/05441066d64e09dd55937d9f089962e9ebe2fb39[WEB]
- https://github.com/strapi-community/strapi-plugin-protected-populate[PACKAGE]
- https://github.com/strapi-community/strapi-plugin-protected-populate/releases/tag/v1.3.4[WEB]